Red Team Notes
⌘Ctrlk
Red Team Notes
  • What is ired.team notes?
    • Pentesting Cheatsheets
    • Active Directory & Kerberos Abuse
    • Red Team Infrastructure
    • Initial Access
    • Code Execution
      • regsvr32
      • MSHTA
      • Control Panel Item
      • Executing Code as a Control Panel Item through an Exported Cplapplet Function
      • Code Execution through Control Panel Add-ins
      • CMSTP
      • InstallUtil
      • Using MSBuild to Execute Shellcode in C#
      • Forfiles Indirect Command Execution
      • Application Whitelisting Bypass with WMIC and XSL
      • Powershell Without Powershell.exe
      • Powershell Constrained Language Mode Bypass
      • Forcing Iexplore.exe to Load a Malicious DLL via COM Abuse
      • pubprn.vbs Signed Script Code Execution
    • Code & Process Injection
    • Defense Evasion
    • Enumeration and Discovery
    • Privilege Escalation
    • Credential Access & Dumping
    • Lateral Movement
    • Persistence
    • Exfiltration
    • Internals
    • Cloud
    • Neo4j
    • Dump Virtual Box Memory
    • AES Encryption Using Crypto++ .lib in Visual Studio C++
    • Reversing Password Checking Routine
Powered by GitBook
For the complete documentation index, see llms.txt. This page is also available as Markdown.
  1. offensive security

Code Execution

regsvr32MSHTAControl Panel ItemExecuting Code as a Control Panel Item through an Exported Cplapplet FunctionCode Execution through Control Panel Add-insCMSTPInstallUtilUsing MSBuild to Execute Shellcode in C#Forfiles Indirect Command ExecutionApplication Whitelisting Bypass with WMIC and XSLPowershell Without Powershell.exePowershell Constrained Language Mode BypassForcing Iexplore.exe to Load a Malicious DLL via COM Abusepubprn.vbs Signed Script Code Execution
PreviousNetNTLMv2 hash stealing using OutlookNextregsvr32